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physical shipping address to the vendor computer (140). The method includes associating the identity and physical location of each 
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ELECTRONIC COMMERCE WITH ANONYMOUS 
SHOPPING AND ANONYMOUS VENDOR SHIPPING 

5 TECHNICAL FIELD 

The present invention relates to a method and system of conducting 
electronic commerce which allows a customer to anonymously visit vendor web sites, 
anonymously purchase goods and anonymously receive goods without disclosing the 
customer's identification and home address information to the web site vendor. 

10 BACKGROUND ART 

At present day, more and more consumers are using a global 
communications network such as the Internet to do their shopping. On-line shopping 
allows users the freedom to quickly browse different vendor web sites, compare prices, 
locate hard-to-find items, shop across the country and the world, all within an abbreviated 

15 period of time. However, for good reasons, many people today are worried about privacy 
issues when using the Internet and World Wide Web ("the web"). Merely by visiting a 
web site, detailed information about the customer can be obtained, such as what computer 
the customer is using, where the computer is connected, which web site the customer last 
visited, etc. Furthermore, more and more sites are requiring that customers log into the 

20 site with personal information in order to use the services of the site. Many customers, 
however, do not wish to compromise their privacy and reveal their name and address since 
it will likely be placed in a database and sold as a part of a mailing list to other companies. 
Further, consumers worry about transmitting personal information such as credit card 
numbers or bank account numbers on-line, for fear of a third-party monitoring their 

25 transmission. . 

At present, Internet billing systems are known that maintains th6 
confidentiality of the customer information by an Internet access provider vis-a-vis a 
vendor web site. The Internet access provider creates access to the Internet through the 
secure provider's web site for the user. The provider then bills the customer's account 

30 with the provider or another specified account for transactions with outside vendors, 
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without to need for ,he — r .0 send Ms bank account number or credn card 

provide comple.e privacy. Whi.c customers using such a billing sysrem do no, have to 
re vea, toir bank accoun, numbers or credi, card numbers ,o ou,side vendors, rhey do need 
t0 reveal rheir home addresses ,0 the vendor so ma. the vendor can maii or sh.p Ore 
customer rbeir order. Many cusromers, when shopping on,ine, wish ,o remain complere.y 
anonymous ro vendors in order to avoid furore so.icirarions from me vendor, as well as 
having the,r names and addresses potentially added ro a maUing Ust. Although anonytmry 
is imporranr, many shoppers enjoy .he benefi. o, remrning .0 vendor web sues which store 
informal abour .he shopper (such as via 'cookies") so .ha, me same informarton need 
no, be reenrered each rime and custom offerings and informa.ion can be communicared ,o 
lh e shopper upon revis.ring a favorire web si,e. Accordingly, whar is needed is a secure 
mterner e-commerce system ,ha, eliminates the need to provide vendors wirh borh 
cusromers' actual identities and shipping addresses, and according provides customers 
with complete anonymity. It would aisobe desirable to provide such an e-commerce 
system whereby me customer can remain anonymous bu, »<ill visit web sites as a character 
or persona such that he or she is recognized upon return ,0 me vendor web sue. 
DISCLOSURE OF THE INVENTION 

in accordance with a preferred aspec, of ,he present invention, a computer- 
, implemented method of deiivering goods is provided whereby good are purchased from a 
vendor having a vendor web she accessible over a computer ne,work by a plurahty of 
cusromers a. physical locations. The cusromers have cusromer computers connected ,0 the 
computer network for accessing the vendor web she and electronicaUy purchasing goods 
therefrom. The method includes: (a) associating me identity and the physical locauon of 
■5 each customer with a respective customer object via Unking information; (b) storms the 
iinking information a. a secure computer a, a location remote from the vendor web s.re; (c) 
anonymousiy connecdng to to vendor web site by to customer computer usurg to 
identity of to cusromer object without revealing to identity and physical locatton of to 
customer; (d) ordering goods a, ,he vendor web sire by to customer using to customer 
30 computer, and upon initiation of an order by to customer, (i) automatically generating a 
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transaction identifier by the vendor computer, (ii) encoding a package of the goods ordered 
by the customer with the transaction identifier by the vendor and (iii) sending the 
transaction identifier together with the customer object to the secure computer by the 
vendor computer; (e) associating the transaction identifier sent by the vendor computer 
5 with the identity and physical address of . the customer at the secure computer using the 
linking information and automatically forwarding the transaction identifier and associated 
identity and physical address of the customer to a computer of a common carrier"; (f) 
delivering the encoded package to the common carrier by the vendor; and (g) reading the 
transaction identifier by the common carrier, using the identity and the physical location of 

10 the customer associated with the transaction identifier and physically delivering the 
package to the physical location of the customer. 

In an alternative preferred embodiment, the computer-implemented method 
of delivering goods comprises (a) associating the identity and the physical location of each 
customer with a respective customer object via linking information; (b) storing the linking 

15 information at a secure computer at a location remote from the vendor web site; (c) 
anonymously connecting to the vendor web site by the customer computer using the 
identity of the customer object without revealing the identity and physical location of the 
customer; (d) ordering goods at the vendor web site by the customer using the customer 
computer, and upon initiation of an order by the customer, encoding a package of the 

20 goods ordered by the customer with the customer object; (e) delivering the encoded 
package to the common carrier by the vendor; (f) providing the linking information to the 
common carrier; and (g) reading the customer object by the common carrier, retrieving the 
identity and the physical location of the customer associated with the customer object and 
physically delivering the package to the physical location of the customer. 

25 Desirably, the above methods further comprise sending information 

representing the cost of the goods ordered by the customer and the customer object front 
the vendor computer to a financial institution computer via the computer network for credit 
approval, ascertaining the credit status of the customer object, and automatically sending a 
message approving or declining credit to the customer to the vendor computer from the 

30 financial institution computer. Ascertaining the credit status of the customer object can also 
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include ascertaining the identity of the customed based on the linking information obtained 
by the financial institution from the secure provider. 

The step of anonymously connecting to the vendor web site may include 
revealing one or more customer characteristics to the vendor web she by the customer 
object so as to allow the vendor web she to use such customer characteristics to customize 
information and goods presented to the customer upon return to the vendor web site using 
the customer object. The step of anonymously connecting to the vendor web sue is 
preferably performed automatically without customer interaction on at least some occasions 
by the customer object programmed to shop for the customer in accordance with directions 
specified by the customer. The customer object may be personified to the customer via the 
customer computer through the display of audio and/or visual display. 

The secure computer may comprise a secure provider computer allowing the 
customers to anonymously connect to the vendor web site therethrough, or alternatively, 
the secure computer can comprise the financial institution computer. 

In another preferred embodiment of the present invention, a computer 
character generating system is provided in the context of a computer system for offering 
goods services and/or information from a vendor computer providing access to a vendor 
web site over a computer network including a plurality of customer computers connected 
to thenetwork for accessing the vendor web site. The computer character generating 
0 system includes (a) a character generate program executable on the vendor computer and 
containing instructions for causing the vendor computer to generate an interactive vendor 
character which represents the vendor and interactively guides a customer through the 
vendor computer site, (b) the character generation program being operative to send 
character display commands to the customer computer when the customer computer has 
accessed the vendor web site causing the customer computer to display on a display device 
associated with the customer computer the interactive vendor character, (c) the interactive 
vendor character providing a trademark function for the vendor such that the interactive 
vendor character is identified with the vendor by customers who desire to acquire goods, 
services and/or information over the computer network from the vendor web site, the 
30 interactive vendor character further having a persona such that the vendor character will 
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respond to inputs from a customer computer representing communications by a customer in 
a manner representative of a human having particular personality traits acting in a 
representative capacity. 

Desirably, the vendor computer records the identities of customer computers 

5 which interact with, the vendor .web site and/ records historical data representing 
transactions of each customer computer with the vendor computer, and the vendor 
character responds to inputs from each customer computer based partially on the inputs 
and partially on the historical data in conjunction with the personality traits. The vendor 
character preferably has an artificial intelligence function which allows the vendor 

10 character to predict responses which would tend to elicit an acquisition by each customer 
computer based upon the historical data associated with such customer computer, and the 
interactive vendor character bases responses at least in part upon such predictions. The 
vendor character can also check for available goods, services and/or information requested 
by each customer computer and also checks for goods or services which are different from 

15 those requested by the customer computer but which are likely to be of interest to such 
customer computer based upon the historical data. The vendor character can be displayed 
with facial expressions, movement characteristics and voice accents associated with the 
personality traits. 

In yet another preferred embodiment of the present invention, an interactive 
20 computer-implemented method of offering goods, services and/or information is provided 
with a vendor computer providing access to a vendor web site over a computer network to 
a plurality of customer computers connected to the network for accessing the vendor web 
site. The method includes (a) providing a plurality of customer objects representing 
individuals who desire to acquire goods, services and/or information from the vendor sites, 
25 each customer object being provided with a set of user characteristics representing personal 
preferences and information about the individual; (b) providing a vendor persona object 
representing the vendor, the vendor persona object being provided with a set of vendor 
characteristics representing information about the goods, services and/or information 
offered by the vendor; and (c) visiting the vendor computer site via the network with a 
30 customer object such that the customer object and the vendor persona object dynamically 
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with one another ,o exchange one or more subsets of the set o, user charaetertsttes 
and vendor characteristics for determining whether the goods, services and/or informal 
offered by the vendor computer site are of .merest to the user persona object. 

The method desirably includes targeting a sales offer by a vendor computer 
„ a, least one customer computer via the secure provider computer based upon the 
purchasing interest and demographic information collected for at .east one customer 
computer by the secure provider computer and provided ,0 the vendor, wherein the 
customer object is configured by the customer ,0 determine whether the sales offer w,« be 

presented to the customer computer. 

In yet a further preferred embodiment of the present invention, a method for 
providing advertising on the web site of a secure provider computer is provided comprising 
(a) providing a secure provider computer to allow customer computers connected to the 
secure provider computer to have access to authorized vendor offers on the secure provider 
web site; and (b) posting one or more vendor offers on the secure provider web sUe, 
15 wherein the offers are only viewable by the customer computers. 

In still a further preferred aspect of the present invention, a computer- 
implemented method for knowingly monitoring network navigation and purchasing history 
of a plurality of customers by a secure provider is provided.comprising: (a) requiring each 
customer to fust establish an account with the secure provider by requiring each customer 
20 to agree to have the customer's demographic information and purchasing history tracked 
by the secure provider; (b) providing on-line access to a computer network to computers of 
customers who have established an account via a secure provider computer of the secure 
provider; and (c) tracking and storing the customers' demographic information and 
purchasing history by the secure provider computer as the customers update and change 
25 their demographic information and make purchases via their customer computers. 

Preferably, at least one customer computer is presented with an item to be 
purchased selected by the secure provider computer based on the customer's demographic 
information and purchasing history tracked by the secure provider. Further, a sales offer 
can be targeted by a vendor computer to at least one customer computer via the secure 
30 provider computer based on the customer's demographic information and purchasing 
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history collected by the secure provide computer and provided to the vendor in a modified 
form which does not include the customers' identity information, wherein the customer 
object is configured by the customer to determine whether the sales offer will be presented 
to the customer computer . 

5 In an even further preferred embodiment of the present invention, a method 

of providing outside vendor offers on a web site of a secure provider computer is 
provided, including (a) establishing a secure provider web site allowing member customer 
computers to have access to an area on the web site that posts outside vendor offers; and 
(b) configuring the secure provider web site so that the vendor offers are only viewable by 

10 the member customer computers. Desirably, only vendors who have signed up with the 
secure provider in advance are able to view the area on the web site that posts the outside 
vendor offers. 

BRIEF DESCRIPTION OF THE DRAWINGS 

FIG. 1 is a schematic diagram of a preferred embodiment of a computer 
15 system according to the present invention. 

FIG, 2 is a flow chart of the steps followed in a preferred method according 
to the present invention. 

FIG. 3 is a depiction of a sample secure provider web site. 
FIG. 4 is a depiction of a sample vendor web site. 
20 BEST MODES FOR CARRYING OUT THE INVENTION 

Referring to FIG. 1, the computer system of the present invention comprises 
a network of interconnected computers connected via a global communications network 
such as the Internet 50. The network of computers comprise plurality of customer 
computers 100, a secure provider computer 110, a plurality of vendor computers 140, a 
25 plurality of bank computers 150 and a plurality of third party carrier or shipping computers 
180. Each computer comprises the typical components needed to connect to the Internet 
and World Wide Web, such as RAM and ROM memory, mass storage, microprocessor(s), 
display device, user input devices, etc. The secure provider computer 110 and vendor 
computers 140 also will typically include one or more server computers to allow provision 
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of web sues such as a secure provtder web site and vendor web sites, which offer goods, 

services and other information desired. 

The present invention desirably allows a eustomer to shop on-line at vendor 
web sires in an anonymous fashion. To do so, a enstomer uses his customer computer 100 
5 (such as a home computer with dial-up connectivity to the Internet) to connect the secure 
provider computer 110 and login with a certificate based ID and password. Pr.or to 
conducting on-line shopping, the eustomer creates a eustomer object or on-.ine personna 
that represents the preferences of the eustomer. This is dtscussed in further detail below. 
The customer object which can be represented by a name (such as "GOLFO") and the 
,0 customer's personal informatton, such as the customer's name and address, are matched up 
with lurking information. Thts linking information is stored, in one embodiment, ,n a 
linking table stored in the database 130 of the secure provider computer 110. Thts hnkmg 
table matches up each customer object with the customer's personal information whtch the 
customer wants shielded from the vendor web sites. A.rernatively, the linking informatton 
■13 can be stored in the database 170 of bank computer 150 so that only the bank, and no. the 
secure provider, actually knows the true identity and address of the customer. In e.ther 
case, the linkmg information is stored in a secure computer so as ,0 shield the hnktng 
information from third parties, tncluding the vendor. Using this linking table, the secure 
provtder computer 110 or the bank computer 150 can determine which customer a gtven 

20 customer object represents. 

Once the customer computer 100 is connected to the secure provider 
computer 110, a secure connection pipeline 120 is provided between the customer 
computer 100 and the secure provider computer 110 in order to prevent transmissions 
between the customer computer 100 and the secure provider computer 110 from bemg 
25 monitored. Namely,. after the customer joins the web site of the secure provider computer 
110, the customer computer 100 is preferably provided with software ^ by the secure, 
provider computer 110. This software enables the customer computer 100 to connect 
directly to the secure provider computer 110, along a known, fixed node-to-node route, 
without having to connect to the vendor web site through a different node-to-node network 
30 each time as is common over the Internet. Thus, to protect the privacy of the user, the 
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customer computers 100 are preferably connected to the secure provider computer 110 
through a virtual personal network ("VPN") which provides a private passageway or 
tunnel through the Internet. As is known in the Internet communications art, in a VPN, 
computers communicate with each other through firewall computers, so that the only 

5 addresses. known are those of the firewall computers. This secure pipeline 120 allows the 
customer to connect directly, node-to-node, with a VPN, when there is communications 
between the secure provider computer and the vendor computer, so the only address that is 
revealed to the vendor is the address of the firewall computer. This allows customer 
computers 100 to communicate from within a network to vendor computers 140 without 

10 having their addresses revealed or access to any peripherals or devices on customer 
computer 100. 

With the secure connection, the customer computer 100 can anonymously 
connect to the web sites of various vendor computers 140 using the Internet via the secure 
provider's proxy servers. The customer computer 100 can browse for the web sites of 

15 vendor computers 140 of interest using various different search methods known in the art. 
When a customer computer 100 connects to a vendor web site of a vendor computer 140, 
the vendor computer 140 is provided only with the customer object, which identifies the 
customer as a fictitious entity without revealing personal information about the customer 
such as real name or address. When the customer computer 100 notifies the vendor 

20 computer 140 that the customer computer 100 would like to make a purchase, the vendor 
computer 140 contacts a bank computer 150 through the Internet to verify that the 
customer object on the customer computer 100 has sufficient funds to make the purchase. 
To facilitate the verification process, the vendor computer 140 forwards the customer 
object to the bank computer. The bank computer 150 obtains or is already provided with 

25 the linking information to link the customer object with personal information about the 
customer, including customer account information. Once the bank 150 
determines whether the customer object has sufficient funds to make the purchase, the 
bank computer 150 notifies the vendor computer 140 whether the customer has sufficient 
funds to make the purchase. In an alternate embodiment, the vendor computer 140 need 
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not contact a bank but can simply bill the secure provider computer 110 for the 
transaction, who will in turn bill the customer. 

Once a purchase by the customer has been approved, the vendor arranges 
for the package to be picked up by a third party carrier. The package, however, must be 
labeled with information that the shipper can use to ship the package to the correct address, 
but cannot contain the actual address of the customer, since it is to be shielded from the 
vendor. To accomplish this, the vendor computer 140, in a preferred embodiment, 
provides the third party carrier computer 180 with a transaction identifier and the customer 
object through the Internet to shipper computer 180. The vendor also places the 
transaction identifier only on the package. Once the shipper comes to the vendor to pick- 
up the package, the shipper, who is provided with or can ascertain the linking information, 
knows the address to match up with the transaction identifier. Alternatively, the vendor 
can simply attach the customer object to the package, such as in the form of a bar code or 
a label. The third party shipper computer 180 can then contact the secure provider 
computer 1 10 directly through a secure pipeline or through the Internet, to retrieve the 
customer's address from the database 130 or is provided ahead of time with the linking 
information to match up the customer object with the customer's actual name and address. 
Alternatively, where the linking information is not known to the secure provider and is 
known only to the bank, the shipper can retrieve or be provided with the linking 
information for the transaction identifier and/or the customer object from the bank. 

FIG. 2 illustrates a preferred method in accordance with the present 
invention. As shown in step 200, a customer computer 100 first connects to the web site 
of the secure provider computer 110, illustrated in FIG. 3, and joins the secure provider's 
service by filling out a standard form on the web site of the secure provider computer 1 10. 
When a customer signs up to use the secure provider web site and services, the customer is 
prompted to create a "persona" or customer object to be stored on a database 130 on the 
secure provider computer 110. In one embodiment, this object may have both a public and 
private segment to a digital certificate or key. In another embodiment, a linking table is 
also stored on the database 130 of the secure provider computer 110 which provides the 
) link between the customer's personal information, such as the customer's name and 



WO 00/14648 



PCT/US99/20348 



10 



15 



- 11 - 

shipping address, and the customer's object such as a public key, but not the synonym, or 
name of the object. Alternatively, the linking table is stored only by banking computer 
and is not known by the secure provider. Thus, while the information about the customer 
object is stored by the secure provider, in the case where the customer wishes to remain 
anonymous to the secure provider, the linking information to link customer object to the 
actual customer is given only to the bank by the customer. The linking table is ultimately 
used to provide the bank computer with the account number or private key authorization of 
the customer and to provide the third party carriers with the actual name and address of a 
customer once the package has been labeled by the vendor with the customer object or 
transaction identifier. 

In one preferred embodiment, the customer can create and modify his 
customer object via a personalized home page stored on the web site of the secure provider 
computer 110. For example, if the customer is a golfer, the customer might create the 
persona or customer object named "GOLFO," which object can then be used to navigate 
_ anonymously on the Internet. In creating the persona, the customers can, for example, 
select an available name (such as GOLFO) and enter in detailed personal information about 
himself. The GOLFO persona thus functions as the customer's anonymous alter-ego and 
will contain personal information such as age, sex, interests, hobbies, shirt size, shoe size, 
likes, dislikes, merchandise the customer has an interest in, etc. This persona, GOLFO, 



~2D along withaTr^meT~ctisrom©rs' personas, is stored on the database 130 of the secure 
provider computer 110, whi^ma^^ the~iiifting information as explained 

above. 

Once the customer joins the web site of the secure provider computer 110, 
the customer is provided with a customer object identifier number or certificate, also 
25 stored on database 130. The customer's object identifier number or certificateT'but not 
their bank account information^ credit card niiT^bers^o^home address, is preferably stored 
on a "cookie" or database at the custoroer^computer 100, and is also stored on secure 
provider computer VjtxC^^^ when a customer logs into the secure provider 

- — " web site vsifig customer computer 100, the customer object identifier number or certificate 
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can be used by the secure provider computer 110 to identify the user as a customer of the 
web site of the secure provider computer 110. 

Once the customer computer 100 has been identified as a member of the 
web site of the secure provider computer 110, the customer computer 100 can then access 
the Internet through the web site of the secure provider computer 110 and begin to securely 
browse, as shown in step 210. 

When the customer computer 100 decides on a web site from which the 
customer would like to make a purchase, such as the vendor web site illustrated in FIG. 4, 
the customer computer 100 enters the web site of the vendor computer 140 as shown in 
step 220, as his "GOLFO" object or persona. Namely, when the customer computer 100 
enters the web site of the vendor computer 140, the vendor computer 140 is provided only 
with GOLFO 's persona information that is authorized for release. The GOLFO persona or 
object provides detailed demographic and psychographic information about the customer so 
that the vendor computer 140, if desired, can develop a relationship with the customer 
through his persona. For example, if the customer visits a golf merchant's web site on a 
regular basis to buy golf shirts, the golf merchant's vendor computer 140 could store a 
profile of the GOLFO persona. When the vendor computer 140 sees that GOLFO has 
returned to the web site, the vendor computer 140 can present the customer, through his 
GOLFO persona, with shirts the vendor may think GOLFO might like based upon the 

previous purchases of GOLFO, as seen by display 400 on me vendor web s ite. 

In other-Avorasr-wte*^^ web site, the customer 

will log in with a customer object that does not reveal the actual customer who is linked to 
the object. The information that is revealed to the vendor would simply be GOLFO at the 
address of the web site ofjhe secure provider computer 110. In this manner, safe and 
private visitation of web sites cari~be achieved through the customer object. The customer 
object can aTso^e -programmed to navigate^the Internet ort its own, gather relevant 
information and then report back to the-actual customer thennformation gathered based on 
the task(s) assigned to the customer object. 

In a further aspect of the present invention, the~custon«r^bject is provided 
with a credit rating or credit history such that the vendor can determine whereto sell the 
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goods to the customer. Preferably, the customer object is provided with its own credit 
facility, which could include, for example, a virtual credit card. Such a virtual credit card 
is preferably given a name and icon representation so that the customer can easily purchase 
goods on-time by clicking on the credit card name or icon displayed at the participating 
5 vendor's web site. Use of such virtual credit card enables the customer object to readily 
purchase goods or services on credit. Credit card transactions, when authorized by the 
customer or customer object identifier, are preferably done through secure transaction 
protocols, such as digital signature and digital certificates. In such a case, the customer 
object itself can be provided with the digital signature and certificate information for use in 
10 purchasing items. 

Once a customer decides to make an on-line purchase from the secure web 
site, the customer preferably clicks on an icon, such as icon 410 shown in FIG. 4, 
representing the virtual credit card on the secure provider web site, as shown in step 230. 
A list of items selectecTcan also be displayed in a "shopping cart" such as shown at display 
15 430 on the vendor web site. 

As shown in step 240, the vendor then forwards the customer's object, 
vendor number, transaction identifier, and the amount of the purchase to bank computer 
150. In one embodiment, the customer object comprises a public key and a private key 
authorization code. In one preferred embodiment, bank computer 150 is provided with a 
20 database 170 of the linking information of customer object or public key and customer 
information that allows the bank computer 150 or credit card company computer to 
determine who the actual customer is. In another embodiment, the bank computer 150 or 
credit card company can retrieve the customer object or public key from the secure 
provider computer 110 and therefore need not be in physical possession of the linking 
25 information. The bank computer 150 then determines whether or not to authorize the 
transaction. Preferably, it is desired that the bank not know the transactional information 
of the customer so that it cannot determine purchasing history and preferences of the actual 
customer. Thus, the bank can agree not to use or sell the customer's transactional 
information for solicitations or the like or, if possible, the bank need not know what is 
30 being purchased and from where, only that the customer has the money or credit to cover 
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the transaction. Thus, in the case where the secure provider is not provided with the 
linking information, the customer is assured that the bank is not monitoring his or bee 
transactional information and that the secure provider, who is monitoring the transactional 
information, cannot. link the customer's actual identity to the customer object. 
5 in another embodiment/vendor computers 140 can contact the secure 

provider computer 110 instead of bank computer 150 to authorize payment The secure 
provider computer 110 can either bill the customer, or the customer can create a 
credit/debit account with the secure provider computer 110. The vendor computer 140 can 
send the secure provider computer 110 a bill for the purchases of the customer computer 
10 100. The secure provider computer 1 10, in turn, can send a bill to the customer computer 
100, or, if the customer computer 100 has a credit or debit account established with the 
secure provider computer 110, the secure provider computer 110 could adjust the 
customer's account accordingly. In another embodiment, the secure provider computer 
110 can engage in electronic bill presentation to customer computer 100, and transmit 
15 information about the request for payment to bank computer 150. 

Once the bank computer 150 has authorized the purchase, as shown in step 
250, the bank computer 150 returns the vendor number, the transaction identifier and/or 
the customer object or public key, and the approval of the transaction back to the vendor 
computer 140 or to the secure provider computer 110, depending upon which computer 
20 transmitted information about the request for payment to bank computer 150. Upon 
approval of the transaction, the vendor readies the goods for anonymous shipment as 
explained below. 

A key aspect of the present invention is the secure and anonymous shipping 
protocol used. This secure and anonymous method is provided whereby the customer can 

25 have the vendor ship the items ordered to the customer without revealing the customer's 
name, address or other information about the customer to the vendor. In one preferred 
embodiment, the present invention uses the transaction identifier that is generated once the 
customer object decides to purchase given items. As shown in step 260, the vendor 
computer 140, once ready to ship the items, contacts an authorized shipper {e.g., a carrier 

30 who has previously contracted with the secure provider) such as carrier computer 180 and 
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discloses only the transaction identifier to the carrier computer 180. In another 
embodiment, the vendor computer 140 provides the carrier computer 180 with the 
customer object (such as "GOLFO"). As shown in step 270, the carrier computer 180 
then contacts the secure provider computer 110 or the bank computer 150 as the case may 
5 be, which then matches up the transaction identifier with the customer. The customer 
information is then relayed by the secure provider computer 110 or bank computer 150 to 
the carrier computer 180 who can then ship the items directly to the customer now 
knowing the address of the customer. Thus, while the secure provider and/or the bank and 
the shipping company know who the customer is, advantageously, the customers actual 
10 identity is shielded from the vendor. 

The customer object can also be used for various other purposes. Thus, in 
another aspect of the invention, the customer object or persona can gather information on 
behalf of the customer and then can communicate with the customer interactively, through 
visual and/or aural means, by using interactive computer techniques such as video 
15 playback and voice synthesis to allow the persona to verbally and/or textual describe what 
information was found. Of course, such information can also be provided in traditional 
formats such as text on the computer screen. In a further aspect of the present invention, 
vendor/customer object interaction can occur through e-mail and e-mail systems can be 
used to further vendor/customer relationships at the object or persona level. In addition, 
20 through e-mail, the secure provider can make direct offerings to the customer whether or 
not the secure provider knows the actual identity of the customer. Thus, vendors and the 
secure provider can send offerings by e-mail to customer objects provided with their own 
e-mail addresses and the customer object can respond to such e-mails with return e-mail or 
by visiting the vendor or secure provider web site. 
25 In order to provide for secure transmissions over the Internet, the present 

invention can use different encryption methods to provide users with anonymity, and to..," 
prevent third parties from improperly obtaining a user's credit card number or bank 
account number. To this end, in one preferred embodiment, the system uses an RSA 
public key encryption. As is known to those skilled in the computer security art, RSA key 
30 technology has two main attributes. First, it can be the basis of a digital signature system. 
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Second, it can be used for storing encryption information. In a RSA digital signature 
system, the public key is used to verify the digital signature. The private key is used to 
sign one's signature for a block of data. Holder's of public keys can verify a purchase by 
requesting that the purchaser digitally sign the block of data. If the signature matches up 
5 with the public key, the identity of the purchaser has been confirmed, and the seller can go 
forward and arrange for the shipment of the device with a third party shipper. 

The customer computer 100 is preferably provided with a private key, while 
the public key is stored on the database 130. The public key will contain information such 
as a customer object and a customer bank account or credit card number. Most 
10 importantly, the public key will not include information such as the customer shipping 
address, as is required in prior art electronic commerce systems. Once the customer 
computer 100 has a public key and a private key assigned, the customer computer 100 can 
then dial onto the Internet through the secure provider computer 110 to begin browsing. 

When a customer computer 100 enters the web site of the vendor computer 
15 140, the vendor computer 140 is provided with the public key. When a customer 
computer 100 notifies the vendor computer 140 that the customer would like to make a 
purchase from the vendor web site 140, the public key, the transaction number and the 
amount of the purchase is then forwarded by the vendor computer 140 to a bank computer 
150. In a preferred embodiment, bank computer 150 will be provided with access to a 
20 database 170 of all public keys. The bank computer 150 can then request that the 
customer computer 100, using the private key, "sign" for the purchase. Based upon the 
response from the customer computer 100, and upon the customer's credit history, the 
bank computer 150 decides whether or not the transaction will be approved. Once the 
transaction is approved, the vendor computer 140 is notified. The vendor computer 140 
25 can then forward the item purchased by the customer with a transaction number or 
customer object to a third party carrier as explained above . Using this transaction number 
or customer object, the carrier computer 180 will be able to retrieve the customer's name 
and home address from the secure provider computer 1 10, or the bank computer 150, and 
can then deliver the package to the customer. 
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In another preferred embodiment of the present invention, customers can 
opt into having the secure provider track their on-line surfing activities and their 
preferences. This is in contrast to web sites which track surfing activity unbeknownst to 
the user. With the present invention, the customer knows ahead of time, by signing up 
. 5 with the secure provider, that the secure provider will be tracking surfing and transactional 
habits so as to better serve the customer. For example* by monitoring the browsing habits 
and purchasing habits of customer computers 100, the secure provider computer 110 can 
determine commonly purchased items or popular vendors. Additionally, the monitoring of 
browsing habits can aid the secure provider computer 110 in predicting future purchases or 
10 services required by the customer object. Using this information, the secure provider can 
purchase large quantities of items commonly purchased by its members, and act as a 
wholesaler for its members, making special deals with the vendors. 

The customer is encouraged by the secure provider to use and educate the 
customer object so that the secure provider can have real-time information to provide just- 
15 in-time or just-ahead-of-time product offerings to the customer or customer object. The 
secure provider computer 110, which will haive acbess to all of the customer data, but not 
necessarily to the customer's identity or address information, can also provide the stored 
demographic and preference information to vendor computers 140 without compromising 
the identity of the customer. In this manner, the provider could allow vendors to send 
20 information to targeted object groups which would not be bothersome to the customer since 
his or her object could make the decision whether to accept the offering from the vendor 
and/or present the offering back to the customer based on the preferences set by the 
customer. Thus, the customer object identifier can be, in effect, a screener of 
"unsolicited" offerings from vendor computers 140. Additionally, the secure provider 
25 computer 110 can conduct market research with a depth unavailable using traditional 
methods. Thus, if the customer computers 100 using customer object identifiers stored on 
the secure provider computers 110 use such object identifiers for many different shopping 
missions, the secure provider computer 110 would have access to data about the entire 
buying habits of its customers. For example, the secure provider database 130 would 
30 include information indicating that particular consumers like BMW automobiles and golf 
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sweaters whereas other consumers like Audi automobiles and cycling jerseys. The secure 
provider computer 110 could conduct statistical studies to uncover correlations that would 
identify potential marketing and buying opportunities. For example, without breaching us 
obligation of confidence with respect to individual consumer information, the secure 
provider could conduct a market research study for a manufacturer of golf sweaters and 
advise the manufacturer to focus on BMW owners rather than Audi owners. 

In another preferred embodiment of the present invention, vendor computers 
140 can provide special offers to be displayed on the web site of the secure provider 
computer 110. To accomplish this, the secure provider computer 110 can provide a web 
page which vendor computers 140 can log onto with a standardized form for the vendors to 
fill out. The secure provider computer 110 can then post each of the standardized forms 
onto a virtual bulletin board to a web site available only to customer computers 100. The 
advantage this embodiment provides is that customers need not shop on a non-secure web 
site to receive the special offers, since the offers will come via the secure provider 
computer 110. -These offers can be posted for all customer computers 100 to see, or can 
be directed to specific customer computers 100. Further, customers will have the option of 
deciding whether or not they wish to even see the offer. 

In order to prevent price pirating, the vendor advertisements are preferably 
posted to an area of the web site of the secure provider computer 110 that is only 
20 accessible to customer computers 100. Accordingly, vendor computers 140 will not be 
able to view the offers coming from other vendor computers 140. Alternatively, 
authorized vendor computers 140 (i.e., vendors signing up with the secured provider to 
reach the secure provider's customers) may be allowed to see one another's offers but 
unauthorized vendors cannot see the offers of authorized vendors. 
25 m yet another aspect of the present invention, an interactive, intelligent 

virtual vendor representative object (such as a virtual salesperson object) is provided as a 
guide to a given web site. For instance, when accessing a web site of a vendor computer 
140, the vendor object can be provided with a persona such that instead of passively 
navigating through the site, an animated character or vendor persona is encountered by the 
30 customer. The vendor persona then takes on the role of a virtual salesperson, asking 
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questions of the customer and making recommendations based on the responses by the 
customer. By interaction with the customer object identifier, the vendor object becomes 
cumulatively knowledgeable, can store customer preferences and history and proactively 
pursue the vendor/ vendee relationship. 

Notoriety of the vendor character or persona apart from the web site is 
desirable and is preferably enhanced through advertising (such as through print media, TV, 
radio, etc.) such that the persona becomes "branded" or closely associated with the vendor 
company and serves as a trademark or service mark of the company. The perception by 
the customer that the vendor character represents the company as a trademark is desirable 
for a number of reasons, such as to impart a feeling of familiarity with the character when 
encountered, create a desire on the customer's part to initially visit the web site to interact 
with the character, and enhance the customer's comfort level in interacting with the 
character. All of these benefits will then ultimately help the vendor increase traffic to the 
web site and raise the comfort level of the customer when he or she visits the web site. 

In a related aspect of the present inventions, intelligent, virtual customer 
objects are desirably provided so that the customer need not search the Internet on his 
own, interact with vendor objects or personae encountered, or deal with the everyday 
hassles of the Internet (expired URLs, slow connections, information overload, etc.). The 
customer can be a customer persona which can be visually displayed on the computer 
screen and be customized or designed to physically resemble the customer's human 
characteristics or resemble a caricature of the customer, a familiar character, an animal, or 
any other visible object. Alternatively, the customer object identifier may be nonvisual or 
simply represented by a file, icon, programming object, etc. Preferably, a customer can 
set up a customer object with all of the characteristics, personal information, history and 
demographic information about the customer such that the object identifier, and not the 
customer, can expend the "effort" of searching the Internet, shopping and gather 
information useful or desired by the customer. It should be noted that the customer object 
is likely to be more proficient than the customer in learning to use Internet or Intranet tools 
that require more effort, knowledge or know how that the average consumer possesses or 
desires to exercise. 
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For instance, a customer object or persona can be provided with 
individualized characteristics about the customer, such as that the customer is male, 32 
years old, a cigar smoker, a wine enthusiast, a tennis player, drives a sedan, owns a house, 
likes gardening, etc. The more information supplied to the persona, the more the persona 
takes on the full characteristics of the customer and enables a "smarter" persona when the 
persona is searching for information. By way of example, if the customer wants the 
persona to shop for light-weight sweaters in a size large, but customer forgets to tell the 
persona that he does not like the color red, the persona may collect possible sweaters to 
buy including unwanted red sweaters. The customer, upon discovering that red sweaters 
were located by his persona, can add a new characteristic to the persona that he does not 
like red sweaters for future search purposes. The more information supplied to the 
persona, the more intelligent it becomes. 

The software provided to both the vendors and customer computers can also 
allow generation of interactive characters. In this regard, the browser of the customer 
computer could be provided with the necessary "plug-ins" (such as a Java plug-in or 
ActiveX control) to allow the rendering of an interactive character on the video screen of 
the customer computer. 

Further, by using artificial intelligence (AI) techniques such as neural- 
network learning, the customer object or persona can be programmed to learn desired and 
undesired characteristics of the customer based on continued interaction between the 
persona and the customer and based on existing preferences. Thus, if the customer has the 
customer persona shop for sweaters, shorts and ties and merchandise is found including 
red sweaters, red shorts and red ties, and the customer selects such items in colors other 
than red, the persona can "learn" through AI techniques that the customer likely does not 
like the color red for clothing items and thus, when sufficiently confident in its assessment, 
will no longer shop for red clothing. Thus, the more and more the customer interacts with 
his persona, the "smarter" the persona becomes and interaction between customer and 
persona is highly encouraged by the present invention. 

Another aspect of the present invention is that the vendor objects can 
interact with the customer objects in a virtual shopping encounter, as if the customer 
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wandered into the store of the vendor and was approached by a salesperson. The customer 
object would relate his preferences (or a subset thereof) to the vendor object who may have 
the items desired by the customer object. If the vendor object, however, does not have 
such an item in stock, it may use the information of the customer object to intelligently 
5 recommend a different item. For instance, if the customer object is looking to buy a 
BMW or Mercedes but the vendor object only has AUDIs, it may recommend to the 
customer object that it consider an AUDI since it deduced that this customer may like 
German-made cars. If the customer object did not specify that it did not like Audi's, it mat 
accept the recommendation from the vendor object. The more often the vendor object 
10 interacts with the customer object, the more each knows or learns of the other's 
preferences, needs and offerings. Such an ever-growing object interrelationship can 
greatly enhance the vendor-customer relationship. 

As these and other variations and combinations of features discussed above 
can be utilized without departing from the present invention as defined by the claims, the 
15 foregoing description of the preferred embodiments should be taken by way of illustration 
rather than by way of limitation of the present invention. 
INDUSTRIAL APPLICABILITY 

The present invention is applicable to the retail industry or elsewhere where 
vendors may wish to display their goods or services at a web site on the Internet and allow 
20 customers to browse and make purchases from a vendor web site anonymously. 
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CLAIMS: 

1. A computer-implemented method of delivering goods purchased 
from a vendor having a vendor web site accessible over a computer network by a plurality 
of customers at physical locations, the customers having customer computers connected to 
5 the computer network for accessing the vendor web site and electronically purchasing 
goods from the vendor web site, comprising: 

(a) associating the identity and the physical location of each customer 
with a respective customer object via linking information; 

(b) storing said linking information at a secure computer at a location 

10 remote from the vendor web site; 

(c) anonymously connecting to the vendor web site by the customer 
computer using the identity of the customer object without revealing the identity and 

physical location of the customer; 

(d) ordering goods at the vendor web site by the customer using the 
15 customer computer, and upon initiation of an order by the customer, (i) automatically 

generating a transaction identifier by the vendor computer, (ii) encoding a package of the 
goods ordered by the customer with the transaction identifier by the vendor and (Hi) 
sending the transaction identifier together with the customer object to the secure computer 

by the vendor computer; 
20 (e) associating the transaction identifier sent by the vendor computer 

with the identity and physical address of the customer at the secure computer using the 
linking information and automatically forwarding the transaction identifier and associated 
identity and physical address of the customer to a computer of a common carrier; 

25 (f) delivering the encoded package to the common carrier by the 

vendor; and 

(g) reading the transaction identifier by the common carrier, using the 
identity and the physical location of the customer associated with the transaction identifier 
and physically delivering the package to the physical location of the customer. 
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2. The method of claim 1, further comprising sending information 
representing the cost of the goods ordered by the customer and the customer object from 
the vendor computer to a financial institution computer via the computer network for credit 
approval, ascertaining the credit status of the customer object, and automatically sending a 

i message approving or declining credit to the customer to the vendor computer from the 

financial institution computer. 

3. The method of claim 2, wherein the secure computer comprises the 

financial institution computer. 

4. The method of claim 2, wherein ascertaining the credit status of the 
3 customer object includes ascertaining the identity of the customer based on the linking 

information obtained by the financial institution from the secure provider. 

5. The method of claim 1, wherein the step of anonymously connecting 
to the vendor web site includes revealing one or more customer characteristics to the 
vendor web site by the customer object so as to allow the vendor web site to use such 

5 .customer characteristics to customize information and goods presented to the customer 
upon return to the vendor web site using the customer object. 

6. The method of claim 1, wherein the step of anonymously connecting 
to the vendor web site is performed automatically without customer interaction on at least 
some occasions by the customer object programmed to shop for the customer in 

20 accordance with directions specified by the customer. 

7. The method of claim 1 , wherein the customer object is personified to 
the customer via the customer computer through the display of audio and/or visual display. 

8. The method of claim 1, wherein the secure computer comprises a 
secure provider computer allowing the customers to anonymously connect to the vendor 

25 web site therethrough. 

9. A computer-implemented method of delivering goods purchased 
from a vendor having a computer web site accessible over a computer network by a 
plurality of customers at physical locations, the customers having customer computers 
connected to the computer network for accessing the vendor computer site and 

30 electronically purchasing goods from the vendor web site, comprising: 



WO 0014648A1 _l_> 



WO 00/14645 



PCT/US99/20348 



-24- 

(a) associating the identity and the physical location of each customer 
with a respective customer object via linking information; 

(b) storing said linking information at a secure computer at a location 

remote from the vendor web site; 
.5 (c) anonymously connecting to the vendor web site by the customer 

computer using the identity of the customer object without revealing the identity and 
physical location of the customer; 

(d) ordering goods at the vendor web site by the customer using the 
, customer computer, and upon initiation of an order by the customer, encoding a package 

10 of the goods ordered by the customer with the customer object; 

(e) delivering the encoded package to the common carrier by the 

vendor; 

(f) providing the linking information to the common carrier; and 

(g) reading the customer object by the common carrier, retrieving the 
15 identity and the physical location of the customer associated with the customer object and 

physically delivering the package to the physical location of the customer, 

10. The method of claim 9, further comprising sending information 
representing the cost of the goods ordered by the customer and the customer object from 
the vendor computer to a financial institution computer via the computer network for credit 

20 approval, ascertaining the credit status of the customer object, and automatically sending a 
message approving or declining credit to the customer to the vendor computer from the 
financial institution computer. 

1 1 . The method of claim 10, wherein the secure computer comprises the 
financial institution computer. 

25 12, The method of claim 10, wherein the secure computer comprises a 

secure provider computer allowing customers to anonymously connect to the vendor web 
site therethrough. 

13. The method of claim 10,, wherein ascertaining the credit status pf the 
customer object includes ascertaining the identity of the customer based on the linking 
30 information obtained by the financial institution from the secure provider. 
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14. The method of claim 9, wherein the linking information is 
transmitted to a computer of the common carrier via the computer network. 

15. The method of claim 9, wherein the step of anonymously connecting 
to the vendor web site includes revealing one or more customer characteristics to the 

5 vendor web site by the customer object so as to allow the vendor web site to use such 
customer characteristics to customize information and goods presented to the customer 
upon return to the vendor web site using the customer object. 

16. The method of claim 9, wherein the step of anonymously connecting 
to the vendor web site is performed automatically without customer interaction on at least 

10 some occasions by the customer object programmed to shop for the customer in 
accordance with directions specified by the customer. 

17. The method of claim 9, wherein the customer object is personified to 
the customer via the customer computer through the display of audio and/or visual display. 

18. In a computer system for offering goods, services and/or information 
15 from a vendor computer providing access to a vendor web site over a computer network 

including a plurality of customer computers connected to the network for accessing the 
vendor web site, a computer character generating system comprising: 

(a) a character generation program executable on the vendor computer 
and containing instructions for causing said vendor computer to generate an interactive 

20 vendor character which represents the vendor and interactively guides a customer through 

the vendor computer site, 

(b) said character generation program being operative to send character 
display commands to said customer computer when said customer computer has accessed 
the vendor web site causing said customer computer to display on a display device 

25 associated with the customer computer said interactive vendor character, 

(c) said interactive vendor character providing a trademark function for 
the vendor such that said interactive vendor character is identified with said vendor by 
customers who desire to acquire goods, services and/or information over the computer 
network from said vendor web site, said interactive vendor character further having a 

30 persona such that said vendor character will respond to inputs from a customer computer 
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representing communications by a customer in a manner representative of a human having 
particular personality traits acting in a representative capacity. 

19. A system as claimed in claim 18, wherein said vendor computer 
records the identities of customer computers which interact with the vendor web site and 
records historical data representing transactions of each customer computer with the 
vendor computer, and wherein said vendor character responds to inputs from each 
customer computer based partially on said inputs and partially on said historical data in 
conjunction with said personality traits. 

20. A system as claimed in claim 19, wherein said vendor character has 
an artificial intelligence function which allows said vendor character to predict responses 
which would tend to elicit an acquisition by each customer computer based upon the 
historical data associated with such customer computer, and said interactive vendor 
character bases responses at least in part upon such predictions. 

21. A system as claimed in claim 20, wherein said vendor character 
checks for available goods, services and/or information requested by each said customer 
computer and also checks for goods or services which are different from those requested 
by said customer computer but which are likely to be of interest to such customer 
computer based upon the historical data. 

22. A system as claimed in claim 18, wherein said vendor character is 
displayed with facial expressions, movement characteristics and voice accents associated 
with said personality traits. 

23. An interactive computer-implemented method of offering goods, 
services and/or information from a vendor computer providing access to a vendor web site 
over a computer network to a plurality of customer computers connected to the network 
for accessing the vendor web site, comprising: 

(a) providing a plurality of customer objects representing individuals 
who desire to acquire goods, services and/or information from said vendor sites, each said 
customer object being provided with a set of user characteristics representing personal 
preferences and information about the individual; 
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(b) providing a vendor persona object representing the vendor, said 
vendor persona object being provided with a set of vendor characteristics representing 
information about the goods, services and/or information offered by the vendor; and 

(c) visiting said vendor computer site via the network with a customer 
5 object such that said customer object and said vendor persona object dynamically interact 

with one another to exchange one or more subsets of said set of user characteristics and 
vendor characteristics for determining whether the goods, services and/or information 
offered by the vendor computer site are of interest to said user persona object. 

24. The method of claim 23, further comprising targeting a sales offer 
10 by a vendor computer to said at least one customer computer via said secure provider 
computer based upon the purchasing interest and demographic information collected for 
said at least one customer computer by said secure provider computer and provided to said 
vendor, wherein said customer object is configured by the customer to determine whether 
the sales offer will be presented to the customer computer. 
15 25. A method for providing advertising on the web site of a secure 

provider computer, the method comprising: 

(a) providing a secure provider computer to allow customer computers 
connected to said secure provider computer to have access to authorized vendor offers on 
the secure provider web site; and 
20 (b) posting one or more vendor offers on the secure provider web site, 

wherein said offers are only viewable by the customer computers. 

26. A computer-implemented method for knowingly monitoring network 
navigation and purchasing history of a plurality of customers by a secure provider 
comprising: 

25 (a) requiring each customer to first establish an account with the secure 

provider by requiring each customer to agree to have the customer's demographic 
information and purchasing history tracked by the secure provider; 

(b) providing on-line access to a computer network to computers of 
customers who have established an account via a secure provider computer of the secure 

30 provider; and 
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(c) tracking and storing the customers' demographic information and 
purchasing history by the secure provider computer as the customers update and change 
their demographic information and make purchases via their customer computers. 

27. The method of claim 26, further comprising presenting at least one 
5 customer computer with an item to be purchased selected by the secure provider computer 

based on the customer's demographic information and purchasing history tracked by the 
secure provider. 

28. The method of claim 26, further comprising targeting a sales offer 
by a vendor computer to at least one customer computer via the secure provider computer 

10 based on the customer's demographic information and purchasing history collected by the 
secure provide computer and provided to the vendor in a modified form which does not 
include the customers' identity information, wherein said customer object is configured by 
the customer to determine whether the sales offer will be presented to the customer 
computer. 

15 _ 29. A method of providing outside vendor offers on a web site of a 

secure provider computer comprising: 

(a) establishing a secure provider web site allowing member customer 
computers to have access to an area on the web site that posts outside vendor offers; and 

(b) configuring the secure provider web site so that the vendor offers are 
20 only viewable by the member customer computers. 

30. The method of claim 29, wherein only vendors who have signed up 
with the secure provider in advance are able to view the area on the web site that posts the 
outside vendor offers. 
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